SinkWise ← Back to home
Legal

Cookie Policy

Last updated: June 30, 2026  ·  Evan Paul Lazar (ABN 76318734086), trading as SinkWise

This Cookie Policy explains how Evan Paul Lazar (ABN 76318734086), trading as SinkWise ("SinkWise," "we," "us," or "our") uses cookies and similar technologies on sinkwise.app (the "Service"), and how you can control them.

What Are Cookies?

Cookies are small data files placed on your device when you visit a website. They're widely used to make websites work, or work more efficiently, and to provide information to the site owner.

Cookies set directly by SinkWise are "first-party" cookies. Cookies set by a service we use (like Stripe, during checkout) are "third-party" cookies.

SinkWise also relies on two related browser-storage technologies, which we treat the same way as essential cookies in this Policy:

  • Local storage — keeps you signed in (Firebase Authentication stores your session here), remembers preferences like dark mode and your AI News region, and caches the last AI Insights / AI News result you generated so it's there when you return.
  • IndexedDB — an on-device cache of your funds, transactions, bills and expenses (Firestore offline persistence) so the app loads instantly and works briefly offline.

Why Do We Use Cookies?

We keep this deliberately simple. SinkWise uses cookies and similar storage for two reasons only:

  • Essential cookies/storage, required for the Service to work — keeping you signed in, securing sensitive actions like password resets and account recovery, protecting against bots and fraud, and caching your data on-device.
  • Optional analytics cookies, which help us understand how the app is used. These are off by default and only switch on if you actively choose to accept them.

We don't use cookies for advertising, and we don't have any third-party ad networks or social-media tracking pixels on the Service.

Your Consent and How to Change It

When you first visit SinkWise, a cookie consent banner asks you to choose. No optional cookies are set until you accept them.

The banner gives you two options: Accept (enables optional analytics cookies) and Reject All (keeps optional cookies off). Essential cookies are not affected by your choice — they are always active because the Service cannot function without them.

Your choice is saved so you're not asked again on every visit. If you change your mind, you can withdraw or change your consent at any time by clearing your browser's cookies and local storage for sinkwise.app and revisiting the site, which will re-show the banner. You can also contact us via our contact page to request a preference reset.

We do not use pre-ticked consent boxes. Consent for analytics is only recorded when you actively click "Accept."

Cookie & Storage Details

Name / typePurposeProviderDurationCan I reject it?
Sign-in session (local storage) Keeps you signed in between visits. Stores your Firebase Authentication token. Firebase Authentication (Google) Until you sign out or the token expires (typically 1 hour, auto-refreshed while active) No — essential. Without it you cannot remain signed in.
sw_reset_binding / sw_recovery_binding (first-party, httpOnly cookies) Securely tie a password-reset or account-recovery link to the device that opened it, so the link can't be reused, shared or opened elsewhere. SinkWise Session (expires when you close the browser tab or within 1 hour, whichever is sooner). Only set when you use those flows. No — security-essential. Only present during a password reset or recovery flow.
On-device data cache (IndexedDB) Caches your funds, transactions, bills and expenses so the app loads instantly and works briefly offline. Firebase Firestore (Google) Persistent until you clear browser storage or delete your account No — essential. Removing it may slow down initial loads.
Preferences & saved AI results (local storage) Remembers your cookie choice, dark mode preference, AI News region, and your last AI Insights / AI News result. SinkWise Persistent until you clear browser storage No — essential to how the app behaves. You can clear it via your browser.
Payment / fraud prevention Supports secure checkout and fraud prevention on Stripe's hosted checkout pages. These cookies are set by Stripe on its own domain when you open a checkout session. Stripe Session to 1 year depending on Stripe's cookie. Only set when you start a checkout. No — only set if you initiate a Premium subscription checkout.
Bot / abuse protection Confirms sign-ups and requests come from a real person and the genuine app (Cloudflare Turnstile on sign-up forms; Google reCAPTCHA / Firebase App Check if enabled for ongoing requests). Cloudflare, Google Session to 30 days depending on the provider No — essential for security. Without these, bot-driven abuse of the Service would be uncontrolled.
Analytics (optional — _ga, _ga_*) Helps us understand how SinkWise is used so we can improve it. Collects anonymised data including pages visited, session duration, and approximate location. No personal financial data is shared with Google Analytics. Google Analytics 2 years for _ga; 2 years for _ga_* (Google Analytics 4 session identifier) Yes — off by default. Only activates if you click "Accept" on the cookie banner. You can opt out at any time by clicking "Reject All" in the banner (re-shown after clearing cookies).

A note on analytics: as of this Policy's last update, we are in the process of finalising our Google Analytics configuration. Until it is fully set up and you have accepted analytics cookies via our consent banner, no analytics cookies are set and no usage data is collected through this channel.

Global Privacy Control (GPC) and Do-Not-Track

Global Privacy Control (GPC): If your browser or a browser extension sends a GPC signal indicating that you do not want your personal information sold or shared, we will honour that signal. Because SinkWise does not sell or share personal information for advertising purposes, a GPC signal has no practical impact on how we use cookies — but we acknowledge it and will not set optional analytics cookies in response to a GPC signal unless you have also actively accepted them via the consent banner.

Do Not Track (DNT): There is currently no uniform legal standard for how websites must respond to browser DNT signals. We do not respond differently to DNT signals but we do honour GPC as described above.

How to Control Cookies Through Your Browser

In addition to our cookie banner, most browsers let you view, delete, or block cookies directly. You can find instructions for your browser here:

  • Google Chrome
  • Mozilla Firefox
  • Apple Safari
  • Microsoft Edge

Please note that blocking essential cookies through your browser settings may prevent SinkWise from working properly — for example, you may be unable to stay signed in.

California Residents — CCPA / CPRA

SinkWise does not sell or share personal information collected through cookies for cross-context behavioural advertising. Accordingly, no "Do Not Sell or Share" opt-out is required for cookies specifically. If you are a California resident and have questions about your privacy rights more broadly, please see the California section of our Privacy Policy or contact us via our contact page.

A Note on AI Features

SinkWise Premium includes AI Insights and AI News. Content these features generate is automated and may be inaccurate, incomplete, or out of date — it is general information only and is not financial, tax, investment, or legal advice. Always verify before acting on it. Full detail is in our Privacy Policy and Terms.

Changes to This Policy

We may update this Cookie Policy from time to time — for example, if we add a new analytics or service provider. We'll update the "Last updated" date above when we do, and material changes will be flagged in-app or by email.

Contact Us

Email: Please contact us through this website's contact page (please include "Cookie Policy" in the message's first line)

Evan Paul Lazar (ABN 76318734086), trading as SinkWise
our contact page

Home Terms & Conditions Privacy Policy Cookie Policy Accessibility Contact